Loading
Generated remediation guidance and an executive summary. No account required.
An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verification is off by default and there is no API for hostname verification.
Use CWE-295, Rust-Openssl Project vendor hub and Rust-Openssl product page to widen CVE-2016-10931 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-20997, CVE-2026-41898 and CVE-2026-41681 for nearby disclosures in the same product family.